Skip to content
CISO Spotlights

Career profile

Richard Marcus

Chief Information Security Officer, AuditBoard

Status
Role as of 19 February 2025, the date of the latest source
Appointed
April 2024
Published

Compiled 8 October 2026 from public records. Each statement below is drawn from the sources listed at the end.

As of February 2025, Richard Marcus is the Chief Information Security Officer of AuditBoard, a role he was appointed to in April 2024.

Career path

Marcus studied finance and entrepreneurship at school rather than coming up through a technical background. He has said this gave him a business-oriented view of cyber risk that differs from peers who enter security through purely technical roles. His first job was in equity research on Wall Street. The 2007–2008 housing crisis led him to change direction, and he joined the startup EdgeCast Networks, working in Security Operations.
He went on to lead global governance, risk and compliance at Verizon Media.
Marcus then joined AuditBoard as Vice President of Information Security, where he worked on the company's SOC 2, GDPR and ISO 27001 compliance programs.
AuditBoard named him Chief Information Security Officer in April 2024, alongside the promotion of Anthony Plachy to General Counsel.
AuditBoard, a cloud-based audit, risk, compliance and ESG platform, agreed to a $3 billion acquisition by private equity firm Hg in May 2024.

Remit at AuditBoard

As CISO, Marcus leads security functions for product, infrastructure and corporate IT, alongside AuditBoard's internal risk and compliance initiatives.
At AuditBoard, the enterprise IT function reports into the security organization rather than standing apart from it. He has described this structure as a way to build security practices into identity and access management and endpoint security, creating what he calls "a secure scaffolding that all other IT goals and objectives hang onto." On supply chain risk, Marcus has pointed to the industry's history of investing heavily in application, infrastructure and enterprise security while having less control over the security practices of smaller suppliers.

Public speaking and published work

Marcus hosted an ISC2 Security Congress session, Third-Party Risk Management: What You Don't Know CAN Hurt You, sponsored by AuditBoard, on May 4, 2023. He is listed in the ISC2 Spotlight speaker directory for governance, risk and compliance alongside figures from organizations including Gartner, Target and Trend Micro. Marcus has written for Dark Reading, including Is Your CISO Navigating Your Flight Path?, published June 3, 2025, and Why Security Leaders Are Opting for Consulting Gigs, published March 5, 2025. Earlier contributions include What InfoSec Pros Can Teach the Organization About ESG, published July 20, 2022.

Sources

  1. 1.
    businesswire.combusinesswire.com · published 18 April 2024 · checked 8 October 2026 · tier A
  2. 2.
    SecurityWeeksecurityweek.com · published 19 February 2025 · checked 8 October 2026 · tier B
  3. 3.
    events.isc2.orgevents.isc2.org · undated page · checked 8 October 2026 · tier B
  4. 4.
    events.isc2.orgevents.isc2.org · undated page · checked 8 October 2026 · tier B
  5. 5.
    Dark Readingdarkreading.com · undated page · checked 8 October 2026 · tier B
  6. 6.
    CSO Onlinecsoonline.com · published 14 June 2024 · checked 8 October 2026 · tier B

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.